svasutin Posted November 20, 2005 Posted November 20, 2005 (edited) I'm trying to verify some values for a sony remover, but I need to check some info out.Wondering if anyone can help.I don't think I can post the final remover or provide a download, but I should be able to post the algorithm and critial entries for removal.This needs to be checked on a clean system.UnderHKLM\System\CurrentControlSet\Enum\PCIIDE\IDEChannel\ You should have two entries, 1 for each channelUnder each key is a sub-key called Control, with a Sting called ActiveServiceI need to confirm the ActiveService value should be the same as the Service key in:HKLM\System\CurrentControlSet\Enum\PCIIDE\IDEChannel\ [channel0/1]in other words, the values ofHKLM\System\CurrentControlSet\Enum\PCIIDE\IDEChannel\ [channel0]\Service=HKLM\System\CurrentControlSet\Enum\PCIIDE\IDEChannel\ [channel0]\Control\ActiveServiceIf someone also checked out the settings for SATA and SCSI devices it would be greatHKLM\System\CurrentControlSet\Enum\ [ SCSI | SATA ] \Service=HKLM\System\CurrentControlSet\Enum\ [ SCSI | SATA ] \Control\ActiveServiceThank you Edited November 20, 2005 by svasutin
svasutin Posted November 21, 2005 Author Posted November 21, 2005 Before doing this, remember you may have to re rip or re download lots of music filesBasically this is what I havelet ccs=ControlSet001 ControlSet002 CurrentControlSetlet group1=DRMSERVER LIM OCTlet group2=cor crater drmserverfor i in [ ccs ] ( for j in [ group2 ] ( for k in valueOf HKLM\System\ i \Services\$sys$ j \Count ( record infected entries for Optical record infected entries for controllers ) ))remove reg entrieshklm\software\$sys$referenceHKLM\SOFTWARE\Microsoft\WBEM\WDM\DREDGEHKLM\SOFTWARE\Microsoft\WBEM\WDMHKLM\SYSTEM\ [ ccs ] \Control\CoDeviceInstallers /v {FF646F80-8DEF-11D2-9449-00105A075F6B} /fNOTE:STILL LOOKING INFO {FF646F80-8DEF-11D2-9449-00105A075F6B}remove reg entries for:HKLM\SYSTEM\ [ CCS ] \Enum\Root\LEGACY_$sys$[ group2 ]remove reg entries for:HKLM\SYSTEM\%CCS%\Services\$sys$[ group2 ]for noted controller listSet \ActiveService Value to ..\Service Valuefor optical...remove files and folders from%windir%\[ system32 | system ]\$sys$filesystemremove %windir%\[ system32 | system ]\caj.dll%windir%\[ system32 | system ]\drivers\%sys$cor.sysFiles I believe are associated with Sony Rootkit$sys$DRMServer.exe$sys$parking.execrater.sysDbgHelp.dlllim.sysoct.sysUnicows.dll <-only remove from $sys$filesystemcaj.dllcor.sys$sys$caj.dll$sys$cor.sys
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now